October 2, 2026
Breaking Into Cyber, Day 1
Over the last year, I’ve been attempting to transition careers, and break into cyber. This year has included: obtaining my Comptia…
By Maury Nickelson
3 min read
Over the last year, I've been attempting to transition careers, and break into cyber. This year has included: obtaining my Comptia Security+ Certification, running through Josh Madakor's Soc Analyst Program/ internship program, and working on projects/ labs. Despite all of that, I have yet to see success because I haven't been consistent. Some months I'm extremly locked in and focused, and other times I let months go by without committing to my goal. That stops now, I've promised myself that I will lock in and be consistent over the next 90 days to make something shake. No zero days, every day I'll study or lab. Time to end the year with a bang and lock in.
Today, 10/2 my day consisted of labbing:
- Watched my desktop have a conversation with 20 servers around the world (knowingly started conversations/ connections). As I've been upskilling, I've realized that most people use and treat computers like magic boxes. In Cybersecurity, computers are treated as systems that can be reasoned.My warmup exercise: Opened Activity Monitor, and looked at the hundreds of processes running. Picked 3 that I didn't recognize and Googled them. Most surprising thing I found was an executable that I've never heard of: CrossDeviceResume.exe- I found that the CrossDeviceResume.exe is a legitimate Windows executable responsible for cross-device continuity
Wazuh SOC Lab, Part 1: Setting Up the Environment
I'm building a SOC detection lab at home using Wazuh. Wazuh is a free, open source SIEM. It pulls logs off machines, checks them against detection rules, and throws alerts when something looks wrong. The end goal for this project is to catch brute force logins and privilege escalation as they happen, then write up how I'd respond to each one like a real analyst would.
Part 1 is just the setup. No detection yet, just getting the pieces in place.
How I set it up
- I built this locally on VirtualBox instead of using the cloud. Four VMs, one host machine.
- The Wazuh Manager runs on Ubuntu Server. This is the main box. It stores the data, runs the rules, and gives me the dashboard I actually look at.
- Then two endpoints, one Linux and one Windows. These are the machines being watched and later attacked. Linux gets hit over SSH, Windows over RDP. I wanted both so the lab isn't one-sided.
- Last is a Kali Linux box. That's my attacker. It runs Metasploit and Hydra and nothing else. No monitoring on it. Its only job is to throw attacks at the other machines so I can see if Wazuh catches them.
Checking the downloads
- Before I installed anything I ran a SHA256 check on every ISO and compared it to the hash the vendor posted. A lot of guides skip this. I did it because the hash proves the file I downloaded is exactly what the vendor put out, not something that got corrupted or messed with on the way down.
- One thing I picked up here: you check the original file the vendor signed, not what it unzips into. Kali comes as a compressed archive, and the posted hash is for that archive, not the disk files inside it. So I verified the download first, then extracted it.
Setting Up VirtualBox with Ubuntu
- The networking part is where people mess up
- The biggest decision in the whole setup was the network, and it's easy to get wrong. VirtualBox has a NAT option and a NAT Network option. They sound the same. They're not.
- Plain NAT gives a VM internet but keeps it walled off from the other VMs. NAT Network gives internet and lets the VMs talk to each other.
- My whole lab needs the machines talking. Agents have to reach the Manager to send logs. The attacker has to reach the targets. So NAT Network was the only option that works. I set mine up on the 10.0.0.0/24 range, so every VM grabs an address on that block automatically and they all sit on the same subnet.
Where I'm at
- The Manager VM is built and Ubuntu is installed, with SSH turned on so I can run it from my host instead of the tiny VM window. Next is installing Wazuh itself, making sure all the services come up, and getting into the dashboard for the first time.
- After that it gets more interesting. Agents, detection rules, and actually attacking my own network to test it.
Part 2 soon!